Spacetrucker Galactic (iOS) — Privacy Policy

Effective date: 2026-06-18. Version 1.1 (v0.3 release — adds the Meshtastic tab).

This is a plain-language privacy policy describing what Spacetrucker Galactic actually does with data. The factual statements below are accurate to the current release build and match the in-app and App Store privacy disclosures.


Summary in one sentence

Spacetrucker Galactic talks to public weather, space-weather, marine, launch, and APRS services on your behalf — it has no backend, no accounts, and no analytics, and nothing about you is ever sent to a Spacetrucker Galactic server because there isn't one.


What we collect

Nothing. Spacetrucker Galactic has no backend, no analytics, no crash reporters, and no advertising SDKs. The app developer (SpaceTrucker2196) operates no servers, no user database, and has no way to see what's in your Spacetrucker Galactic install.

The only third-party Swift package linked into the app is Apple's Apache-2.0 swift-protobuf, scoped to the Meshtastic tab so it can decode the wire format your Meshtastic node speaks. swift-protobuf is a pure-Swift serialisation library — it has no telemetry, no analytics, and never makes a network request of its own.

What the app sends out

Every outbound request goes to a single public service:

DestinationWhat is sentWhy
api.weather.govYour latitude and longitude (rounded to 4 decimals)NWS forecast for your area
tgftp.nws.noaa.govA marine zone ID (e.g. GMZ033), only if you set oneNWS marine bulletin
services.swpc.noaa.govNothing identifying — a generic GETSpace weather (Kp index, 10.7 cm flux)
ll.thespacedevs.comNothing identifying — a generic GETUpcoming launches list
api.aprs.fiA callsign you've added + the aprs.fi API key you entered in SettingsHam radio position lookup

Your User-Agent is included on every request (NWS requires one). The default identifies the app and version; you can change it in Settings.

Meshtastic tab — Bluetooth only, never the internet. When you use the Mesh tab, the app pairs with a nearby Meshtastic node over Bluetooth LE. The node is short-range hardware you own. Messages you send go from your iPhone to that node, and from there onto the mesh radio network — they never traverse the internet through Spacetrucker Galactic. Other apps on your phone do not see this Bluetooth connection.

What the app stores on your device

DataWherePurposeWhen deleted
Saved APRS callsigns (call, label, notes)UserDefaultsQuick selection in the Callsigns tabRemove from the Callsigns tab, or delete the app
Your aprs.fi API keyUserDefaults (SecureField on input)Callsign position lookupsClear it in Settings, or delete the app
Default marine zoneUserDefaultsConvenienceClear it in Settings
User-Agent stringUserDefaultsSent with HTTP requestsReset in Settings
Notification enable flags + next-fire timesUserDefaultsSchedule local remindersTurn off in Settings, or delete the app
Pending local notificationsiOS notification center (system-managed)Fire golden-hour and astronomical-dusk alertsTurn off in Settings; iOS clears the queue
Meshtastic traffic + chat historySwiftData store under the app's Library/Application Support/Meshtastic.storeShow recent mesh activity when you reopen the Mesh tabTap "Clear history" in the Mesh tab's STATUS section, or delete the app

All of the above is stored inside the app's private container on this device (iOS sandbox; no other app can read it without jailbreaking). The Meshtastic store is pinned to the app's own sandbox — not the App Group container that the widget reads from — so Mesh chat and traffic stay private to the main app.

What the app does not do

When data leaves the device

The only paths data takes off your device are user-initiated, and they go to public services rather than to us:

1. Forecast requests. When you refresh, your latitude/longitude goes to NWS, your marine zone (if set) goes to the NOAA marine text bulletin server, and generic requests go to SWPC and The Space Devs. 2. Callsign lookups. When you tap a saved callsign, the callsign and your aprs.fi API key go to aprs.fi. 3. Meshtastic mesh radio. When you tap Send in the Mesh tab, the message goes over a short Bluetooth LE link to your paired Meshtastic node, which then transmits it on the mesh radio network. Spacetrucker Galactic is not in that radio path — it only hands the bytes to your node. 4. iCloud Backup. Apple's standard device backup may include the app's UserDefaults and SwiftData stores if you have iCloud Backup enabled in iOS Settings. That is the operating system doing this, not Spacetrucker Galactic — the app never uploads anything to iCloud directly.

Children

Spacetrucker Galactic is not directed at children. The expected user is an adult traveler, sailor, photographer, or ham operator. Age rating: 4+, with no objectionable content, no user-generated content, and no in-app purchases.

Cookies, beacons, web tracking

The Spacetrucker Galactic iOS app does not embed a web view that loads remote content. Taps on links open in your default browser (Safari), and Spacetrucker Galactic sends no data with those URLs.

Changes to this policy

If what Spacetrucker Galactic does with data changes, this page will be updated and the version number above will be bumped. The App Store will require re-confirmation of the privacy disclosures for the next release.

Contact

This policy is hosted at spacetrucker2196.github.io/StatusGalactic-iOS/privacy.

To ask a question about this policy or about how Spacetrucker Galactic handles data, email support@river.io. We respond within a few business days.


← back to Spacetrucker Galactic